October: ICS Security Month In Review

Published: Nov. 2, 2020, 1:30 p.m.

Jason Nations and I go over October's top three stories plus our Win, Fail and Prediction of the month.

 

Top Stories

1. Six Sandworm attackers from Russia charged. Why was this done now and what does it accomplish?

2. More ICS vendors announced security services (ABB and Siemens). Will this be a good business? Is it good for asset owners?

3. ICS security vendors are creating risk metrics for cyber assets and zones (Claroty and ID announced). How should asset owners view these metrics?

Plus Jason has a Win and Prediction, and I give my Win, Fail and Prediction for October.

Links

Jason Nations / Selena Larson S4x20 video - Understanding Our Adversaries

Thomas Rid's Active Measures book

ICS-Patch Decision Tree ... What To Patch When?

Finite State web page and Unsolicited Response episode